Privacy
Your draft starts on your device—and stays there until you decide otherwise.
SitSorted is designed around data minimisation. This page explains what stays in your browser, what is stored when you choose account features, and how to contact us about your information.
Public generators
Answers are saved in your browser’s local storage, separately for each tool, and expire after 30 days of inactivity. Creating, reloading, copying and printing a draft does not transmit generator field values to SitSorted.
If storage is unavailable, the tool still works for the current page session and tells you that autosave is unavailable.
Owner accounts and import
Invited owners sign in by email magic link. A local draft remains local after sign-in. Only an explicit final confirmation imports the reviewed content. Import receipts retain a fingerprint and operational metadata, never another copy of the raw draft.
Owner access requests
When you request owner access, the form sends the name and email address you provide through Resend to support@sitsorted.com. A person reviews each request and responds manually. Submitting the form does not create an account or guarantee access.
The request is not added to a marketing list or written to the SitSorted product database. If access is approved, the email address may later be added manually to the invite allowlist; subsequent authentication and account records are handled as described in this notice.
- Request emails are kept only while needed to review and respond to the request.
- We may keep limited correspondence for longer when necessary to record an access decision, prevent abuse, resolve a dispute or meet a legal obligation.
- Request details are deleted when they are no longer needed for those purposes.
- You can withdraw a pending request or ask about its retention by emailing support@sitsorted.com.
Live sitter briefs
A sitter link is a private bearer secret. The raw token is shown once, while only its cryptographic digest and last four characters are stored. On exchange, the browser receives a short-lived secure cookie and moves to a token-free URL. Every sitter request rechecks that the link is still valid.
What the product does not ask for
- Exact home addresses, access codes, alarm codes or Wi-Fi credentials.
- Payment details, microchip numbers, uploads or full medical records.
- In-app chat messages, advertising profiles or third-party tracking identifiers.
Limited product analytics
SitSorted accepts only allowlisted coarse events and enums. It rejects names, draft or issue text, contacts, tokens, full URLs, exact dates, IP addresses and user-agent strings. Daily network rate-limit keys are HMAC-derived, not retained as raw IP addresses. The included database migration schedules hourly deletion of event rows older than 90 days and expired rate-limit rows after their 48-hour lifetime. Analytics and rate-limit writes also run the same cleanup as a fallback.
Browser storage and essential cookies
The free tools use local browser storage so a draft can survive a reload. Signed-in owner sessions and opened sitter briefs use secure, essential cookies for authentication and access control. SitSorted does not use advertising cookies or third-party behavioural tracking.
Outreach and partnerships
SitSorted may contact an incorporated organisation at a published editorial, partnerships or resource-submission address when a specific free guide or tool appears relevant to its audience. We use publicly available business-contact details for limited, individually researched business outreach under our legitimate interests in responsibly introducing SitSorted. We do not use bulk sequences, purchased lists or email tracking pixels.
We do not cold-email sole traders, personal addresses or organisations whose corporate status is uncertain without consent. Every message identifies SitSorted, links to this notice and provides a clear way to opt out.
- Records may include the organisation and domain, relevant resource page, public contact source, business email address, fit notes, contact dates, response, opt-out and any resulting placement.
- Ordinary prospect records are deleted 12 months after the last contact.
- When someone objects, we keep only the minimum address or domain and objection date needed to honour that suppression.
- To object, opt out or ask about these records, email support@sitsorted.com.
Your choices and contact
SitSorted is an independent online service based in England. For privacy questions or requests, email support@sitsorted.com. This address is not an emergency channel.
- Clear any local draft immediately from its tool.
- Archive completed trips and restore them later through account settings.
- Submit or cancel a verified account-deletion request through account settings.
- Revoke or replace a sitter link to end existing access.
Retention and your rights
Local drafts expire after 30 days of inactivity. Event-level analytics are deleted after 90 days and expired rate-limit buckets after 48 hours. Account and trip information is retained while it is needed to provide the service or meet a valid legal obligation. Depending on your circumstances, you may ask for access, correction, deletion, restriction or a portable copy of personal information, or object to certain uses, including business outreach. You may also complain to the UK Information Commissioner’s Office.